Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

ether — Vulnerabilities & Security Advisories 10

Browse all 10 CVE security advisories affecting ether. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Ether serves as a decentralized cryptocurrency platform enabling smart contracts and decentralized applications (dApps). Historically, vulnerabilities have included remote code execution (RCE), cross-site scripting (XSS), and privilege escalation flaws, often stemming from smart contract coding errors or platform weaknesses. Notable incidents include the 2016 DAO hack exploiting a reentrancy vulnerability, resulting in $50 million stolen, and the 2020 DeFi flash loan attacks manipulating price oracles. Security characteristics emphasize immutability of transactions but highlight risks in third-party integrations and smart contract implementations. The platform's open nature exposes it to continuous threat vectors, requiring rigorous auditing and developer awareness to mitigate risks.

CVE ID Title CVSS Severity Published
CVE-2026-55086 Etherpad: Import/export use Math.random() for temp file paths; predictable paths on shared /tmp enable symlink-based file overwrite — etherpad CWE-59 4.2 Medium 2026-08-19
CVE-2026-55085 Etherpad: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in etherpad-lite — etherpad CWE-79 9.6 Critical 2026-08-19
CVE-2026-55089 Etherpad: JWT `admin` claim presence-only check lets non-admin OAuth users invoke every Etherpad HTTP API endpoint — etherpad CWE-863 9.9 Critical 2026-08-19
CVE-2026-55090 Etherpad: Stored XSS in HTML export via unescaped attribute-pool values — etherpad CWE-79 5.3 Medium 2026-08-19
CVE-2026-55088 Etherpad: Device-to-device author-token transfer endpoint is replayable, never expires, and exposes the cleartext author token — etherpad CWE-200 6.8 Medium 2026-08-19
CVE-2026-55087 Etherpad: x-proxy-path header reflected into admin HTML/JS/CSS (cache-poisoning XSS) and concatenated into redirect (open-redirect) — etherpad CWE-79 6.1 Medium 2026-08-19
CVE-2009-10007 Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks — Catalyst::Plugin::Authentication CWE-384 - - 2026-06-09
CVE-2025-40920 Catalyst::Authentication::Credential::HTTP versions 1.018 and earlier for Perl use insecurely generated nonces — Catalyst::Authentication::Credential::HTTP CWE-340 7.4AI High AI 2025-08-11
CVE-2025-40907 FCGI versions 0.44 through 0.82, for Perl, include a vulnerable version of the FastCGI fcgi2 (aka fcgi) library — FCGI CWE-1395 9.8AI Critical AI 2025-05-16
CVE-2021-43802 Admin privilege escalation and arbitrary code execution via malicious *.etherpad imports — etherpad-lite CWE-790 9.9 Critical 2021-12-09

This page lists every published CVE security advisory associated with ether. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.